Fun

News Feed - 2023-11-25 06:11:59

Tom Blackstone2 hours agoBlast network hits $400M TVL, rebuts claim that it’s too centralizedThe Blast team responded to claims that its multisignature upgrade functionality makes it too centralized.311 Total views3 Total sharesListen to article 0:00NewsJoin us on social networksWeb3 protocol Blast network has gained over $400 million in total value locked (TVL) in the four days since it was launched, according to data from blockchain analytics platform DeBank. But in a Nov. 23 social media thread, Polygon Labs developer relations engineer Jarrod Watts claimed that the new network poses significant security risks due to centralization.


The Blast team responded to the criticism from its own X (formerly Twitter) account, but without directly referring to Watts’ thread. In its own thread, Blast claimed that the network is as decentralized as other layer 2s, including Optimism, Arbitrum and Polygon.On multisig security.

Read this thread to understand the security model of Blast along with other L2s like Arbitrum, Optimism, and Polygon.— Blast (@Blast_L2) November 24, 2023


Blast network claims to be “the only Ethereum L2 with native yield for ETH and stablecoins,” according to marketing material from its official website. The website also states that Blast allows a user’s balance to be “auto-compounded” and that stablecoins sent to it are converted into “USDB,” a stablecoin that auto-compounds through MakerDAO’s T-Bill protocol. The Blast team has not released technical documents explaining how the protocol works, but it says they will be published when the airdrop occurs in January.


Watts’ original post said Blast may be less secure or decentralized than users realize, claiming that Blast “is just a 3/5 multisig.” If an attacker gets control of three out of five team members’ keys, they can steal all of the crypto deposited into its contracts, he alleged."Blast is just a 3/5 multisig..."

I spent the past few days diving into the source code to see if this statement is actually true.

Here"s everything I learned:— Jarrod Watts (@jarrodWattsDev) November 23, 2023


According to Watts, the Blast contracts can be upgraded via a Safe (formerly Gnosis Safe) multisignature wallet account. The account requires three out of five signatures to authorize any transaction. But if the private keys that produce these signatures become compromised, the contracts can be upgraded to produce any code the attacker wishes. This means an attacker who pulls this off could transfer the entire $400 million TVL to their own account.


In addition, Watts claimed that Blast “is not a layer 2,” despite its development team claiming so. Instead, he said Blast simply “accepts funds from users” and “stakes users’ funds into protocols like LIDO” with no actual bridge or testnet being used to perform these transactions. Furthermore, it has no withdrawal function. To be able to withdraw in the future, users must trust that the developers will implement the withdrawal function at some point in the future, Watts claimed.


Additionally, Watts claimed that Blast contains an “enableTransition” function that can be used to set any smart contract as the “mainnetBridge,” which means that an attacker could steal the entirety of users’ funds without needing to upgrade the contract.


Despite these attack vectors, Watts claimed he did not believe Blast would lose its funds. “Personally, if I had to guess, I don’t think the funds will be stolen,” he stated. But he also warned that “I personally think it’s risky to send Blast funds in its current state.”


In a thread from its own X account, the Blast team stated that its protocol is just as safe as other layer-2s. “Security exists on a spectrum (nothing is 100% secure),” the team claimed, “and it’s nuanced with many dimensions.” It may seem that a non-upgradeable contract is more secure than an upgradeable one, but this view can be mistaken. If a contract is non-upgradeable but contains bugs, “you are dead in the water,” the thread stated.


Related:Uniswap DAO debate shows devs still struggle to secure cross-chain bridges


The Blast team claims the protocol uses upgradeable contracts for this very reason. However, the keys for the Safe account are “in cold storage, managed by an independent party, and geographically separated.” In the team’s view, this is a “highly effective” means of safeguarding user funds, which is “why L2s like Arbitrum, Optimism [and] Polygon” also use this method.


Blast is not the only protocol that has been criticized for having upgradeable contracts. In January, Summa founder James Prestwich argued that the Stargate bridge had the same problem. In December 2022, the Ankr protocol was exploited when its smart contract was upgraded to allow 20 trillion Ankr Reward Bearing Staked BNB (aBNBc) to be created out of thin air. In the case of Ankr, the upgrade was performed by a former employee who hacked into the developer’s database to obtain its deployer key.# Ethereum# Hackers# Cybersecurity# Hacks# DeFi# Layer2# StakingAdd reactionAdd reactionRead more3 things we might see from crypto as 2023 winds to an endWill the next crypto bull run be dominated by L1s, L2s or something else?Layer 2 networks hit $13B TVL, but challenges still remain

News Feed

Fantom allocates $120M in FTM tokens for Sonic migration
Amaka Nwaokocha14 hours agoFantom allocates $120M in FTM tokens for Sonic migrationThe fund will be used for native application grants, strategic grants to decentralized applications, and the development of infrastructur
OpenAI makes ChatGPT ‘less verbose,’ blurring writer-AI distinction
Amaka Nwaokocha1 hour agoOpenAI makes ChatGPT ‘less verbose,’ blurring writer-AI distinctionThe update could worsen the ongoing challenge of writers sounding like AI despite having written the articles themselves.370
‘New nine’ Spot Bitcoin ETF volumes reach new daily high as BTC nears $55K
Brayden Lindrea1 hour ago‘New nine’ Spot Bitcoin ETF volumes reach new daily high as BTC nears $55KBlackRock’s IBIT made up more than 50% of the daily trading volume and even smashed its own daily record by more th
Dogecoin Cofounder Faces Harassment While ‘Meme Coin’ Hype Trends Among Investors
Dogecoin Cofounder Faces Harassment While "Meme Coin" Hype Trends Among Investors As dogecoin’s frenzy keeps making the headlines in the crypto sphere, som
Stablecoin Market Cap Slides, BUSD and DAI Valuations Jump, Fiat Tokens Represent 70% of All Crypto Trades
Stablecoin Market Cap Slides, BUSD and DAI Valuations Jump, Fiat Tokens Represent 70% of All Crypto Trades During the last month, the stablecoin economy’s market valuation d
SEC doesn’t want Ethereum to transform banking landscape, says Joseph Lubin
Gareth Jenkinson9 hours agoSEC doesn’t want Ethereum to transform banking landscape, says Joseph LubinEthereum co-founder Joseph Lubin says the SEC is engaging in strategic enforcement action instead of meaningful disc
Serenity Shield’s token falls nearly 99% after MetaMask wallet breach
Brayden Lindrea7 hours agoSerenity Shield’s token falls nearly 99% after MetaMask wallet breachThe Serenity Shield team said it is “actively working” to redeploy all liquidity to new token contracts and will replac
Credit Agency Moody’s Looks to Hire Crypto Analyst, Strong Understanding of Defi Important
Credit Agency Moody"s Looks to Hire Crypto Analyst, Strong Understanding of Defi Important One of the Big Three credit rating agencies, Moody’s Corporation, often referred t
Dogecoin Still In Consolidation – Analyst Expects $0,63 If We Get A Breakout
Este artículo también está disponible en español. Dogecoin (DOGE) has been stuck in a range for nearly a month, struggling to break above the $0.44 resistance level. Desp
William Suberg9 hours agoBitcoin institutional inflows top $1B in 2023 amid BTC supply squeezeBitcoin and altcoins are beneficiaries of major inflows this year, while the question of a BTC supply squeeze remains.2428 Tot
Coinbase and 17 Other Crypto Firms Launch ‘Travel Rule Universal Solution Technology’
Coinbase and 17 Other Crypto Firms Launch "Travel Rule Universal Solution Technology" On Wednesday, the publicly-listed cryptocurrency firm Coinbase announced the launch of a colla
Ex-Coinbase Manager’s Brother Sentenced to Prison in Crypto Insider Trading Case
Ex-Coinbase Manager"s Brother Sentenced to Prison in Crypto Insider Trading Case A former Coinbase employee’s brother has been sentenced to 10 months in prison in what the U.